Vultur
Malware⚠️ Overview
Vultur is an Android banking trojan first documented in early 2021 by researchers at ThreatFabric, attributed to a Spanish-speaking threat actor tracked as “Vultur Group.” It belongs to the Remote Access Trojan (RAT) and information stealer category, specifically targeting financial applications on Android devices through overlay attacks and accessibility service abuse.
🔧 Technical Capabilities
Vultur propagates primarily via malicious SMS messages (smishing) that lure victims into installing a dropper app disguised as legitimate utilities (e.g., “Protect” or “Update”). It exploits Android’s Accessibility Service API to perform keylogging, screen recording, and overlay attacks that capture banking credentials, credit card numbers, and two-factor authentication codes. The malware uses a custom C2 protocol over HTTPS, with command-and-control servers often hosted on compromised domains; it maintains persistence by registering as a device administrator and disabling Google Play Protect. Evasion techniques include obfuscation of its code using commercial packers, dynamic code loading, and checking for emulator environments to avoid analysis. Vultur also intercepts SMS messages to bypass SMS-based OTPs, and it can initiate USSD codes to perform actions like call forwarding.
📜 History & Notable Incidents
Vultur first emerged in February 2021 targeting Italian banks, as reported by Cleafy. In 2022, it expanded to Spanish financial institutions and was linked to a campaign that distributed the dropper through Google Play Store listings before they were taken down. No specific CVEs are associated with Vultur itself, but it abuses Android Accessibility Service (MITRE ATT&CK ID T1621) and pre-installed device admin privileges. Law enforcement actions include Google removing multiple malicious apps in 2022, but the group remains active.
🔍 Detection Indicators
Known indicators include package names such as “com.secure.cleaner” or “com.sms.free” observed in early campaigns; SHA256 hashes include a06f3c7e… (per ThreatFabric report). Behavioral signatures include granting Accessibility Service to a suspicious app, excessive SMS reading permissions, and unusual network connections to IP addresses in the 185.234.xx.xx range. Registry keys on Android are not applicable; instead, look for device admin activation and persistent notification to avoid removal. User-Agent strings often mimic standard Android browsers (e.g., “Mozilla/5.0 (Linux; Android 10)…”).
☠️ Risk & Impact
Vultur enables full account takeover of online banking and cryptocurrency wallets, leading to direct financial theft. Victims have reported losses ranging from hundreds to tens of thousands of euros, primarily in the banking and fintech sectors across Southern Europe. The malware also exfiltrates contact lists and device information, which may be used for further social engineering attacks.
🛡️ Mitigation
Mitigation includes avoiding sideloaded apps and disabling “Install from unknown sources” on Android. Organizations should deploy endpoint detection solutions that monitor Accessibility Service abuse (e.g., CrowdStrike Falcon for Android) and enforce strict app vetting policies in enterprise environments. No specific patch exists, but keeping Google Play Protect enabled and using behavioral-based mobile threat defense tools significantly reduces risk.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.